roll

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the install path is mostly legitimate same-org npm tooling, but the skill has notable internal inconsistencies about what 'Roll' service it targets, and it routes authenticated requests through Membrane as an intermediary rather than clearly to an official Roll API. This is not confirmed malware, but the purpose mismatch and proxy-based data flow make it higher risk than a normal single-service integration guide.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 04:06 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Froll%2F@fa15d22bc91dd1b80d7aebaceeae60866bbd68c8
Security Audit — socket — roll